To do that someone would already have to have typed your OS password to unlock your screen, right? If you're in the habit of leaving your system unlocked when you're not around it, you're already inviting someone to install a keylogger.
Gpg-agent is super awesome and flexible. Google it -- you'll dig it.
But, for the moment, we ARE talking about simplicity. I'd like to simply encrypt a plaintext file. Then I'd have a decrypting version of cat (call it "dcat") that asks me for a password, doesn't echo it, and applies it to the file before cat'ing. It doesn't know if the password is right or wrong; it just passes the file through it before cat'ing. If I give it the wrong password, gibberish comes out.
I could then view a whole file (dcat my_secret_pancake_recipe.txt) or pipe it to grep (dcat my_logins.txt | grep -A 2 Netflix) to get just the lines I want---exactly what you'd do with any text file except that it starts with a decryption that asks for a password (which it doesn't echo).
What's the best way to do something this simple?
UPDATE: openssl essentially does this and comes already installed on Mac OS X. I'm a crypto noob, though, so I'd still welcome advice.
But GPG in general is the de facto unix way to go about crypting things. Straight up openssl is good for somethings, making little shell scripts like "dcat" is nice for others, but for general purpose encryption of files, nothing really beats GPG.
I guess GPG isn't simple. It's a big project, well-vetted, and has been under development for years. The usage of its tools, though, is very simple, and the file formats have now become an acceptable standard, widely adopted all over.
So really, give GPG another shot and a close look before you knock it. If it still doesn't meet what you're looking for, check out the man page for openssl-enc. Probably what you want is something like "openssl enc -aes-256-ofb -in infile -out outfile -salt", but likely there are other nuances to account for too. Be careful with crypto.
[1]: Switched to 1password a while back oddly enough, to achieve some simplicity.
https://github.com/drakedevel/pyagilekeychain/blob/master/ag...
Not that standard (the encryption is standard AES, but not OpenPGP format) but it is certainly portable.
It sounds like pass has the potential to do these things as well, and I would prefer to use an open platform over a closed one, all things being equal. Just recognize that there are tradeoffs.
So stop whining, and write this component; it's easy.
You would get a lot further in convincing people to use and contribute to your app if you toned down the condescension. I like your app and support unix tools with open formats but you come across as someone who would be very difficult to work with.
Sorry you're put off by my dismissal. My inbox is filled with awesome patches and suggestions from people, and things have been going pretty smoothly with integrating these and fleshing out new features. You seem optimistic about the project (" I think it has the potential to be better than those other password managers"), and so if you've got the impetus to contribute some code or suggestions, by all means send me an email.
bash tab completion...